CS0-003: Incident Response & Management
Incident Response & Management is one of the skill areas tested on the CySA+ (Cybersecurity Analyst) (CS0-003) exam. Below are free CS0-003 practice questions with worked answers and a concept diagram — each with a plain-language explanation. Practice the first 10 questions of CS0-003 free, no signup.
The concept, in one picture
2 free CS0-003 Incident Response & Management questions
A SOC analyst at an online retailer notices an unfamiliar external IP address performing port sweeps and Nmap service-version probes against the company's public-facing web servers over several hours. No exploit attempts or malicious payloads have been observed. Which phase of the Cyber Kill Chain does this activity represent?
- Actions on objectives
- Command and control
- Exploitation
- ✓ Reconnaissance
Port sweeps and service-version scanning are information-gathering: the attacker is mapping the target's attack surface before attempting anything else, which is the reconnaissance phase — the first step of the Cyber Kill Chain. Exploitation would require the attacker to actually trigger a vulnerability on a target system, and the stem explicitly states no exploit attempts have been seen. Command and control describes compromised internal hosts beaconing out to attacker infrastructure, which requires a foothold that does not exist here. Actions on objectives is the final phase, where the attacker carries out their end goal such as data theft — far beyond mere scanning.
The SOC at a payments company confirms indicators of compromise on a production database server and plans to disconnect it from the network for containment. Following the order of volatility, which of the following should responders capture FIRST, before the server is isolated?
- A full forensic image of the system drive
- ✓ The server's active routing table
- Copies of the suspicious executables found on disk
- The contents of the recovery partition
- The statically assigned IP address on the interface
The order of volatility says to collect the most transient data first. Network state such as the active routing table (along with ARP cache and open connections) lives in memory and can change or vanish the moment the host is isolated or restarted, so it must be captured before containment. The system drive, the recovery partition, and any suspicious executables are all persistent on disk and will still be there after isolation, so they can be imaged later. A statically configured IP address is stored in configuration and is trivially recoverable at any time, making it the least urgent item of all.
Practice CS0-003 free
The first 10 questions of every exam are free. No signup, no email wall.
Start practicing →Get a free CS0-003 study plan by email
A short plan to work through CS0-003 by skill area, plus a note when we add new questions. Optional — the practice above stays free. No spam, unsubscribe anytime.